Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 13.04: USN-1990-1 Moderate: X.Org X Server Input Issue

ubuntu
Calendar Grey October 17, 2013
Scroller Ubuntu
The latest update for the X.Org server resolves critical vulnerabilities that could cause system crashes and enable unauthorized admin access via crafted inputs
The X.Org X server could be made to crash or run programs as an administrator if it received specially crafted input.

Summary

The X.Org X server could be made to crash or run programs as an

administrator if it received specially crafted input.

Software Description:

- xorg-server: X.Org X11 server

- xorg-server-lts-quantal: X.Org X11 server

- xorg-server-lts-raring: X.Org X11 server

Details:

Pedro Ribeiro discovered that the X.Org X server incorrectly handled

memory operations when handling ImageText requests. An attacker could use

this issue to cause X.Org to crash, or to possibly execute arbitrary code.

(CVE-2013-4396)

It was discovered that non-root X.Org X servers such as Xephyr incorrectly

used cached xkb files. A local attacker could use this flaw to cause a xkb

cache file to be loaded by another user, resulting in a denial of service.

(CVE-2013-1056)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  xserver-xorg-core               2:1.13.3-0ubuntu6.2

Ubuntu 12.10:
  xserver-xorg-core               2:1.13.0-0ubuntu6.4

Ubuntu 12.04 LTS:
  xserver-xorg-core               2:1.11.4-0ubuntu10.14
  xserver-xorg-core-lts-quantal   2:1.13.0-0ubuntu6.1~precise4
  xserver-xorg-core-lts-raring    2:1.13.3-0ubuntu6~precise3

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1990-1

CVE-2013-1056, CVE-2013-4396

Severity
important
Lowest
Low
Medium
High
Critical

October 17, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.